Skip to content
.ca
sign in

Threat intelligence from Zscaler ThreatLabz

38 reports on cyfar.ca summarizing Zscaler ThreatLabz research. Visit Zscaler ThreatLabz

Zscaler ThreatLabz8 days ago8 minLLM reportmedium

Cyberattacks once again Trap Black Friday Shoppers | Zscaler

Zscaler ThreatLabz observed a seasonal spike in web skimming and phishing campaigns targeting Black Friday and Cyber Monday shoppers. The Grelos skimmer group injected obfuscated JavaScript into e-commerce sites (both Magento and WooCommerce) to capture payment card data, using cookies for staging and base64 encoding for exfiltration disguised as benign traffic. Attackers also compromised legitimate deal websites to redirect users to malicious domains, and numerous newly registered holiday-themed domains were observed.

Zscaler ThreatLabz9 days ago10 minLLM reporthigh

A Study of Thanos Ransomware Variants | Zscaler Blog

Thanos ransomware, a C#/.NET-based RaaS platform whose builder source code leaked, spawned at least four double-extortion variants in 2021: Prometheus, Haron, Spook, and Midas. All variants share common signatures including the 'GotAllDone' file marker appended to encrypted files and key identifiers in ransom notes. The latest variant, Midas, terminates security and backup services, deletes shadow copies, disables the Raccine anti-ransomware tool, encrypts files using Salsa20 with RSA-wrapped keys, and maintains persistence via a startup LNK file.

Zscaler ThreatLabz10 days ago7 minLLM reportmedium

Facebook Phishing Attacks: How Credential Theft Works

Zscaler ThreatLabz identified six Facebook phishing domains registered on 02/13/2011 by the same individual in China. The domains host identical fake Facebook login pages that capture user credentials before redirecting victims to legitimate Facebook or Google. The campaign leverages fast-flux DNS with rapidly rotating IP addresses and a shared DNS server (fbnameserver.com) previously tied to other Facebook phishing operations, making takedowns and blocklisting difficult.

Zscaler ThreatLabz12 days ago11 minLLM reporthigh

Technical Analysis of GoGRPC | ThreatLabz

ThreatLabz documents a threat actor cluster, likely an initial access broker for ransomware operations, that gains access via Microsoft Teams vishing and Quick Assist remote sessions, then deploys PowerShell staging scripts to install a multi-variant Go-based backdoor (GoGRPC) that communicates over gRPC/HTTP2 - an unusual choice for external C2 that blends with legitimate application traffic. The toolkit has expanded to include additional backdoors, SOCKS proxy tunneling tools (RevSocket, PyGRPC, RSOX), and an S3-based exfiltration utility (S3Siphon), reflecting increasing sophistication and selective targeting of corporate/enterprise environments since mid-2026.

Zscaler ThreatLabz13 days ago8 minLLM reportmedium

Black Friday Deals: Trojans, Phishing, Crypto Coin Mining

Zscaler ThreatLabZ documents a seasonal increase in malicious activity coinciding with Black Friday/Cyber Monday shopping, including domain squatting on the '.blackfriday' TLD to impersonate Google and distribute the Fareit and Loki infostealers, browser-based cryptocurrency mining scripts embedded in shopping-themed sites, fraudulent e-commerce storefronts, and spear-phishing documents using holiday bonus/gift card lures to deliver embedded malicious applications. The techniques primarily rely on social engineering and typosquatted infrastructure rather than software exploitation.

Zscaler ThreatLabz14 days ago10 minLLM reporthigh

Return of Emotet malware | Zscaler

Emotet, a prolific banking-trojan-turned-initial-access-broker, returned to the threat landscape on November 14, 2021 following a law enforcement disruption and arrests in January 2021. The revived variant is being distributed via the TrickBot botnet and direct spam campaigns using reply-chain phishing emails with malicious macro-enabled Office documents and password-protected archives, and now communicates with C2 infrastructure over HTTPS with updated encryption compared to prior versions.

Zscaler ThreatLabz14 days ago6 minLLM reportlow

Hey AndroGuard, I Will Crash Your Python Buddy! | Zscaler

The article describes anti-analysis techniques found in certain Android malware samples designed to crash the AndroGuard APK analysis tool or its Python zipfile dependency, similar to anti-debugging tricks used by PC malware against tools like OllyDbg and IDA Pro. Techniques include crafting malformed 'linksize'/'linkoff' padding values that trigger unpack() failures due to 4-byte alignment issues in zipfile.py, and manipulating AndroGuard's search_methods() return values to conceal malicious behaviors like audio recording. The AndroGuard project addressed the zipfile parsing issue in a December 2012 patch.

Zscaler ThreatLabz17 days ago11 minLLM reporthigh

China-nexus Group Targets Arabian Gulf Region | ThreatLabz

A China-nexus threat actor, assessed with medium confidence to be Mustang Panda, conducted a multi-stage attack campaign targeting the Arabian Gulf region using Middle East conflict-themed social engineering lures. The attack chain delivered a PlugX backdoor variant through a ZIP archive containing a malicious LNK file that downloaded a CHM file via cURL, extracted a TAR archive using hh.exe, and used DLL sideloading to execute heavily obfuscated shellcode. The PlugX variant supports HTTPS and DNS-over-HTTPS (DOH) for C2 communication and employs advanced obfuscation including control flow flattening, mixed boolean arithmetic, corrupted MZ/PE headers, and reflective DLL injection.

Zscaler ThreatLabz19 days ago9 minLLM reporthigh

Domain Fronting Attack: CDN Abuse & C2 Evasion Explained

Domain fronting is a network evasion technique where an attacker conceals the true destination of HTTPS traffic by using a trusted domain in the TLS SNI field while specifying a different malicious destination in the HTTP Host header, both served by the same CDN. The article details real-world abuse of Azure, Cloudflare, and Discord CDNs for C2 traffic and phishing, and describes domain hiding via ESNI as a related emerging threat. Effective defense requires full TLS inspection with SNI-Host header mismatch detection and ESNI stripping at the proxy layer.

Zscaler ThreatLabz19 days ago10 minLLM reporthigh

Targeted Attack on Middle East Govts (Part 1) | ThreatLabz

Zscaler ThreatLabz identified a multi-stage attack campaign targeting Middle East government entities by a threat actor linked to East Asia. The attack chain uses an ISO file to deliver the TELESHIM backdoor via DLL sideloading of a legitimate ASUS executable, with TELESHIM abusing the Telegram API for C2 communication. A second-stage loader, MIXEDKEY, uses environmental keying based on the victim's volume serial number to decrypt and reflectively load the final BINDCLOAK C2 implant, with heavy obfuscation and anti-analysis techniques throughout.

Zscaler ThreatLabz23 days ago9 minLLM reporthigh

GuLoader Malware Obfuscation Techniques Analyzed

GuLoader is a highly obfuscated malware-as-a-service downloader that has evolved since 2019 to deliver secondary payloads such as RATs and information stealers. It employs polymorphic code for dynamic constant construction, exception-based control flow obfuscation using five distinct CPU exception types, encrypted strings with stack-based decryption, and modified DJB2 API hashing. Payloads are hosted on trusted cloud platforms (Google Drive, OneDrive) to evade reputation-based detection, and the malware continues to receive updates increasing analysis complexity.

Zscaler ThreatLabz24 days ago10 minLLM reporthigh

ClaudeFix: Shared Claude Chats Meet ClickFix | Zscaler

A MacSync Stealer campaign abuses Anthropic's Claude shared chat platform to host ClickFix-style malicious instructions, using Google malvertising to lure macOS users searching for Claude. Victims are tricked into running a Base64-obfuscated curl command that pipes a zsh script to execution, which in turn downloads and pipes a second stage to osascript. The stealer collects keychain data, browser credentials, cryptocurrency wallets, cloud keys, and user files, exfiltrating them in 10MB chunks via HTTP PUT before deleting all traces.

Zscaler ThreatLabzabout 1 month ago9 minLLM reportmedium

Indirect Prompt Injection Targets AI Agents | ThreatLabz

Zscaler ThreatLabz identified two campaigns leveraging Indirect Prompt Injection (IPI) to manipulate AI agents via malicious websites. The first campaign uses SEO poisoning and hidden IPI instructions on a fraudulent API documentation site to trick AI agents into sending cryptocurrency payments for a fake API key. The second campaign uses a typosquatting domain (debank.auction) with hidden prompt injection to misclassify the fraudulent site as the legitimate DeBank platform. Testing across 26 LLMs showed 4 models vulnerable to the payment scam and 2 models susceptible to misclassification, demonstrating measurable real-world impact that varies by model and context.

Zscaler ThreatLabzabout 2 months ago5 minLLM reporthigh

Edgecution: Malicious Edge Extension Backdoor | ThreatLabz

ThreatLabz identified a new attack campaign deploying 'Edgecution,' a malicious Microsoft Edge browser extension used by an initial access broker affiliated with Payouts King ransomware. The malware abuses the Chrome native messaging protocol to bridge a headless browser extension with a Python-based backdoor, enabling arbitrary code execution and filesystem access while evading traditional browser sandboxes.

Zscaler ThreatLabzabout 2 months ago5 minLLM reporthigh

SmartApeSG Supply Chain Attack Targets Okendo | ThreatLabz

ThreatLabz identified a supply chain attack where the threat actor SmartApeSG compromised the widely used Okendo Reviews widget to inject malicious JavaScript. The loader employs environment checks, XOR deobfuscation, and staged execution to deliver ClickFix-style social engineering lures, ultimately aiming to deploy RATs and information stealers on desktop endpoints.

Zscaler ThreatLabzabout 2 months ago5 minLLM reporthigh

What the ThreatLabz 2026 Phishing and Initial Access Report Means for the Public Sector | Zscaler

The ThreatLabz 2026 Phishing and Initial Access Report highlights a shift towards highly targeted, AI-enabled phishing campaigns against the public sector. Despite a 20% overall drop in phishing volume, attackers are increasingly utilizing AI site builders, encrypted delivery channels, and AiTM/BiTM techniques to bypass traditional MFA and secure initial access.

Zscaler ThreatLabzabout 2 months ago6 minLLM reporthigh

AI Generated ClickFix Attack Delivers SmartRAT | ThreatLabz

ThreatLabz identified a ClickFix campaign utilizing AI-generated typosquatting domains to impersonate Brazilian banks and deliver a PowerShell-based banking RAT dubbed SmartRAT. The malware establishes persistence via scheduled tasks or Windows services, communicates over a custom TCP protocol on port 51888, and features advanced capabilities including keylogging, fake banking overlays, and QR code interception for financial fraud.

Zscaler ThreatLabzabout 2 months ago6 minLLM reportcritical

Shai-Hulud: Miasma, Hades, & AI Scanner Evasion | ThreatLabz

The Shai-Hulud software supply chain campaign has significantly evolved, expanding from npm to PyPI and shifting from maintainer compromise to CI/CD abuse. Recent waves demonstrate advanced techniques including OIDC token scraping to bypass SLSA provenance, IDE configuration file weaponization, and prompt injection designed to evade LLM-based security scanners.

Zscaler ThreatLabzabout 2 months ago4 minLLM reporthigh

Zscaler ThreatLabz 2026 Phishing and Initial Access Report

The Zscaler ThreatLabz 2026 Phishing and Initial Access Report highlights a shift from high-volume phishing to highly targeted campaigns leveraging AI site builders and encrypted channels. Attackers are increasingly utilizing AiTM and BiTM techniques to bypass MFA, while conducting massive reconnaissance via cloud infrastructure to identify exposed entry points.

Zscaler ThreatLabz2 months ago6 minLLM reporthigh

Technical Analysis of MLTBackdoor | ThreatLabz

ThreatLabz has identified MLTBackdoor, a highly obfuscated post-exploitation framework delivered via ClickFix social engineering lures. The malware utilizes Mixed Boolean-Arithmetic (MBA), Control Flow Flattening (CFF), and indirect system calls to evade detection, while maintaining persistence and control through a custom encrypted protocol, a Domain Generation Algorithm (DGA), and a Beacon Object File (BOF) loader.